GwisinLocker is a ransomware family discovered in 2022 that targets organizations in South Korea. It supports both Windows and Linux environments, including VMware ESXi, making it capable of disrupting both endpoint and virtualized server infrastructure. Reported behavior includes broad file encryption across compromised systems, use of AES and RSA in its encryption workflow, and deployment of ransom notes to pressure victims into payment. The malware can shut down virtual machines, although that behavior is not enabled by default in observed reporting. GwisinLocker is part of the broader trend of ransomware operators expanding from traditional Windows encryption to Linux and hypervisor-focused attacks against enterprise virtualization platforms. High-confidence reporting supports its use as a financially motivated ransomware operation targeting South Korean companies.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation cited as one of several non-Babuk-based strains targeting VMware ESXi virtual machines.
Ransomware targeting companies in South Korea, including Linux/ESXi environments, with optional VM shutdown capability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.